CVE-2025-59921

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*

History

16 Oct 2025, 14:47

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Fortinet
Fortinet fortiadc
References () https://fortiguard.fortinet.com/psirt/FG-IR-23-434 - () https://fortiguard.fortinet.com/psirt/FG-IR-23-434 - Broken Link

14 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 16:15

Updated : 2025-10-16 14:47


NVD link : CVE-2025-59921

Mitre link : CVE-2025-59921

CVE.ORG link : CVE-2025-59921


JSON object : View

Products Affected

fortinet

  • fortiadc
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo